Christian Grothoff 5a6952fe90 [libmicrohttpd] [digest-auth]: bug in hash algorithm
From: 
Andreas Wehrmann <a.wehrmann@centersystems.com>
  To: 
libmicrohttpd@gnu.org
  Date: 
Today 08:58:43 am
   
  Spam Status: Spamassassin 0% probability of being spam.

Full report:
Probability=No, score=-3.2 required=7.0 tests=AWL,BAYES_00 autolearn=ham version=3.2.5-tuminfo_1  
Hello!

I wrote a little testpage that I deliver using libmicrohttpd using 
digest authentication.
The testpage consists of four files (framed page + image file).
When I initially connected to the webserver via the browser it correctly 
challenged me
for my credentials. However, after entering the username and password 
the index file
got loaded but it happened that the browser then challenged me again for 
each
additional file to be loaded.
Since this is very annoying I tried increasing the nonce table size to 3000
(was default) but it was no good.
I then dug a little deeper and found out, that the hash algorithm to 
determine the index
for a given nonce always returned zero thus overwriting other nonces.
The offending line is at check_nonce_nc() in digestauth.c:313:

off = (off << 8) | (*np & (off >> 24));

whereas is should be:

off = (off << 8) | (*np ^ (off >> 24));

Since "off" is initialized with zero and an unsigned integer
a logical AND returns zero which is not right obviously.
After this fix, the server challenged me only once and I got "random" 
indices.
I found the problem in libmicrohttpd 0.9.5.

Best regards,
Andreas Wehrmann

-- 
Dipl.-Ing. (FH) Andreas Wehrmann
Software Development
--------------------------------------------------------------
Center Communication Systems GmbH
A-1210 Wien, Ignaz-Köck-Straße 19
Sitz in Wien
FN 796 88p, Firmenbuchgericht Wien
www.centersystems.com

Tel.: +43 (0) 190 199 - 3616
Mobile: +43 (0) 664 884 75916
Fax: +43 (0) 190 199 - 2110
E-Mail: a.wehrmann@centersystems.com
2011-01-18 23:00:02 +00:00
2010-09-23 05:16:15 +00:00
2010-07-25 10:30:29 +00:00
2010-07-26 16:57:47 +00:00
2009-02-19 19:17:23 +00:00
2011-01-10 13:11:13 +00:00
2009-10-11 13:01:59 +00:00
2010-01-18 07:58:14 +00:00
2007-01-10 04:12:34 +00:00

About
=====

libmicrohttpd is a GNU library (part of the GNU project) written in C
that provides a compact API and implementation of an HTTP 1.1 web
server (HTTP 1.0 is also supported).  libmicrohttpd only implements
the HTTP 1.1 protocol.  The main application must still provide the
content.


Installation
============

If you are using Subversion, run "autoreconf -fi" to create configure.

In order to run the testcases, you need a recent version of libcurl.
libcurl is not required if you just want to install the library.

Especially for development, do use the MHD_USE_DEBUG option to get
error messages.


Configure options
=================


If you are concerned about space, you should set "CFLAGS" to "-Os
-fomit-frame-pointer" to have gcc generate tight code.

You can use the following options to disable certain MHD features:

--disable-https: no HTTPS / TLS / SSL support (significant reduction)
--disable-messages: no error messages (they take space!)
--disable-postprocessor: no MHD_PostProcessor API
--disable-dauth: no digest authentication API

The resulting binary should be about 30-40k depending on the platform.


Portability
===========

The latest version of libmicrohttpd will try to avoid SIGPIPE on its
sockets.  This should work on OS X, Linux and recent BSD systems (at
least).  On other systems that may trigger a SIGPIPE on send/recv, the
main application should install a signal handler to handle SIGPIPE.

libmicrohttpd should work well on GNU/Linux, BSD, OS X, W32 and z/OS.
Note that HTTPS is not supported on z/OS (yet).  We also have reports
of users using it on vxWorks and Symbian.  Note that on platforms
where the compiler does not support the "constructor" attribute, you
must call "MHD_init" before using any MHD functions and "MHD_fini"
after you are done using MHD.


Notes on compiling on z/OS:
---------------------------

After extracting the archive, run

iconv -f UTF-8 -t IBM-1047 contrib/ascebc > /tmp/ascebc.sh
chmod +x /tmp/ascebc.sh
for n in `find * -type f`
do
  /tmp/ascebc.sh $n
done

to convert all source files to EBCDIC.  Note that you must run
"configure" from the directory where the configure script is
located.   Otherwise, configure will fail to find the
"contrib/xcc" script (which is a wrapper around the z/OS c89
compiler).


Development Status
==================

This is a beta release.  Below we list things that should be
implemented (in order of importance) before we can claim to be
reasonably complete.


Untested features:
==================
- add testcases for http/1.1 pipelining (need
  to figure out how to ensure curl pipelines 
  -- and it seems libcurl has issues with pipelining, 
  see http://curl.haxx.se/mail/lib-2007-12/0248.html)
- add testcases for resource limit enforcement
- add testcases for client queuing early response,
  suppressing 100 CONTINUE
- extend testcase for chunked encoding to validate
  handling of footers
- more testing for SSL support
- MHD basic and digest authentication


Functions not covered by "make check":
======================================
- file_reader (response.c); special case (sendfile)
- mhd_panic_std (daemon.c); special case (abort)
- MHD_poll (daemon.c)
- parse_options (daemon.c)
- MHD_set_panic_func (daemon.c)
- MHD_get_version (daemon.c)


Missing documentation:
======================

- manual:
  * document configuration options
  * document details on porting MHD (plibc, z/OS)
S
Description
No description provided
Readme
20 MiB
Languages
C 86.4%
M4 10.3%
Shell 1.9%
Makefile 1.3%